Scammers steal $2M in ETH as fake GIWA network fools DYORSWAP

Scammers tricked DYORSWAP into connecting to a fake GIWA bridge and siphoned roughly $2 million worth of Ether, the DEX said in a reconstruction. GIWA — an L2 project by Upbit operator Dunamu — warned the network’s mainnet had not launched and called circulating connection details false.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 2 minutes agoUpdated 2 minutes ago0 views
Scammers steal $2M in ETH as fake GIWA network fools DYORSWAP

Why It Matters

The incident highlights risks around fake network endpoints and bridge infrastructure, and it prompted the affected DEX to compensate users from its own funds while tracing the attacker. It also underscores operational security challenges for projects scaling L2 deployments and cross-border trials.

Key Facts

  • Estimated value stolen: About $2 million in ETH
  • ETH received by fraudulent bridge: ~767.65 ETH from 1,335 addresses
  • ETH drained by scammers: 766.25 ETH
  • Compensation paid by DYORSWAP: More than 200 ETH from DYORSWAP's own funds
  • DYORSWAP statement: Contracts were not compromised; tracing of bridge deployer, funding sources, suspected test wallets and recipient addresses is ongoing.

Decentralized exchange DYORSWAP reported that attackers used a counterfeit GIWA bridge to steal around 766.25 ETH — roughly $2 million — after the fraudulent contract accepted about 767.65 ETH from 1,335 addresses. In a reconstruction the DEX published, it said it initially mistook the malicious bridge for GIWA’s mainnet before realizing the connection details were fake.

GIWA, the Ethereum layer-2 network developed by Upbit operator Dunamu, posted a warning that its mainnet was not running and that purported mainnet connection information circulating online was false. The project previously launched a Sepolia testnet in September 2025 using Optimism’s OP Stack and in April had agreed with Hana Financial and POSCO International to test a GIWA Chain-based cross-border remittance system using real trade transactions.

DYORSWAP emphasized that its smart contracts themselves were not compromised. The exchange said it is actively tracing the bridge deployer, the sources of funding, suspected test wallets and the addresses that received the laundered funds. To help affected users, DYORSWAP reported it had paid out more than 200 ETH from its own treasury as compensation.

The case illustrates the dangers around misconfigured or spoofed network endpoints and the exposure of bridge processes when users or services connect to unverified contracts. DYORSWAP’s public reconstruction and GIWA’s denial together aim to clarify the sequence of events while investigations continue.

Keep Reading